Cyber Explained

What is MFA — and why does it matter so much?

MFA is the single most effective security step most businesses can take — and it’s simpler than you think. Here’s what it is and why it stops so many attacks.

Greater Manchester & UK-wide · free, no-obligation advice

Why Foresight

  • Cyber Essentials Plus certified
  • Supporting 130+ organisations since 2006
  • We reply within one working hour
  • Plain-English, no jargon

Quick answer

MFA (multi-factor authentication) means proving who you are with more than just a password — usually a code or an approval on your phone, or a security key. It matters because passwords get stolen, leaked and reused constantly; MFA means a stolen password alone isn’t enough to get in. It’s one of the single most effective security steps any business can take, blocks the vast majority of account-takeover attacks, and is now expected for Cyber Essentials and cyber insurance.

How it works

Something you know, plus something you have

Your password is something you know. MFA adds something you have — your phone or a security key. So even if a criminal steals or guesses your password, they still can’t log in without that second factor. It’s a small step with an enormous payoff.

The types

Not all MFA is equal

MethodNotes
Authenticator app (push/code)Recommended — secure and easy
Security keyStrongest option, phishing-resistant
SMS text codeBetter than nothing, but weaker — avoid where you can

Why it matters so much

It stops the most common attack

Most break-ins today use stolen or reused passwords — exactly the credentials traded on the dark web. MFA defeats that, which is why it blocks the overwhelming majority of account-takeover attempts, and why it’s now effectively required for Cyber Essentials and cyber insurance.

Where to turn it on

Start here

Turn MFA on everywhere you can — email first, then banking, Microsoft 365, social media and any system holding sensitive data. For businesses, we enforce MFA properly across Microsoft 365 as part of our security baselines, so it’s consistent and can’t be switched off.

FAQs

Common questions

What is MFA?
MFA (multi-factor authentication) means logging in with more than just a password — typically a code or approval on your phone, or a security key — so a stolen password alone isn’t enough to get in.
Why is MFA so important?
Because most attacks rely on stolen or reused passwords. MFA blocks the vast majority of account-takeover attempts and is now expected for Cyber Essentials and cyber insurance.
Is an authenticator app better than SMS?
Yes. App-based approval (or a security key) is more secure than SMS text codes, which can be intercepted. Use an authenticator app or key where you can.
Does MFA stop phishing?
It stops the most common outcome of phishing — a stolen password being reused — because the attacker still lacks your second factor. Phishing-resistant MFA like security keys is stronger still.
Where should I enable MFA first?
Your email account — it’s the key to resetting everything else. Then banking, Microsoft 365, social media and any system with sensitive data.

Is MFA switched on everywhere it should be?

We’ll enforce MFA properly across your Microsoft 365 so a stolen password is never enough.